Malicious PDF — malware analysis report

Static analysis result for SHA-256 4b034c2a46838358…

MALICIOUS

PDF

16.5 KB Created: 2019-05-02 05:26:30 +01:00 Authoring application: mPDF 5.7
MD5: 8912050791da1af43cb2a31da833e495 SHA-1: 206b24f131f281aeaeed2bd6d9112b3536438d1f SHA-256: 4b034c2a46838358db36968d81d2c6b395d5a919841b313848af1dd821a9273d
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, primarily hosted on the domain 'loaminoo.linkpc.net'. This behavior is indicative of a link farm or a redirection scheme designed to lead users to potentially malicious content. No scripts were extracted, and the document body was heavily obfuscated, making it difficult to determine the exact user-facing lure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4098091096097095/Three-Cheers-for-Tacky-by-Helen-Lester.pdf
    • http://loaminoo.linkpc.net/3099095095094097/The-Loch-Mess-Monster-by-Helen-Lester.pdf
    • http://loaminoo.linkpc.net/1096092094092091/Amanda-Lester-and-the-Orange-Crystal-Crisis-Amanda-Lester-Detective-2-by-Paula-Berinstein.pdf
    • http://loaminoo.linkpc.net/1091095093094091097/Instructor-s-Resource-Manual-To-Accompany-The-Penguin-Handbook-And-Brief-Penguin-Handbook-Second-Edition-by-Susan-Schorn.pdf
    • http://loaminoo.linkpc.net/6097092097094098/True-And-Tacky-Ii-More-Weird-Stories-From-The-World-s-Newswires-by-Carolyn-Naifeh.pdf
    • http://loaminoo.linkpc.net/5094097096095091/Enter-Helen-The-Invention-of-Helen-Gurley-Brown-and-the-Rise-of-the-Modern-Single-Woman-by-Brooke-Hauser.pdf
    • http://loaminoo.linkpc.net/3095094095099098/The-Good-Life-Helen-and-Scott-Nearing-s-Sixty-Years-of-Self-Sufficient-Living-by-Helen-Nearing.pdf
    • http://loaminoo.linkpc.net/1096093097095098/Pstalemate-by-Lester-del-Rey.pdf
    • http://loaminoo.linkpc.net/1095098092095090/Once-Upon-a-Time-by-Lester-del-Rey.pdf
    • http://loaminoo.linkpc.net/1096091090092092/Nerves-by-Lester-del-Rey.pdf
    • http://loaminoo.linkpc.net/2095095093094098/Lady-Helen-and-the-Dark-Days-Club-Lady-Helen-1-by-Alison-Goodman.pdf
    • http://loaminoo.linkpc.net/4098090099091097/Our-Island-by-Alison-Lester.pdf
    • http://loaminoo.linkpc.net/4098091096096099/My-Farm-by-Alison-Lester.pdf
    • http://loaminoo.linkpc.net/1098097090091097/When-Dad-Killed-Mom-by-Julius-Lester.pdf
    • http://loaminoo.linkpc.net/2098098096099094/Saturdays-and-Teacakes-by-Lester-L-Laminack.pdf
    • http://loaminoo.linkpc.net/1090097094090097094/Overlooked-Treasures-by-Lester-V-Beitz.pdf
    • http://loaminoo.linkpc.net/7091093095095093/Forest-of-the-Sprites-by-Lester-Ferguson.pdf
    • http://loaminoo.linkpc.net/1096099094096099/The-Quicksand-Pony-by-Alison-Lester.pdf
    • http://loaminoo.linkpc.net/2092098099096091/Three-Hens-and-a-Peacock-by-Lester-L-Laminack.pdf
    • http://loaminoo.linkpc.net/3097099095093095/The-French-Photographer-by-Natasha-Lester.pdf
    • http://loaminoo.linkpc.net/5094097096095091/Enter-Helen-The-Invention-of-He